Integrate locations
This commit is contained in:
1 parent
aa9b16088e
commit
89138887cc
4 files changed
+69
-66
No files matched your search
@@ -1,5 +1,5 @@
|
||||
#!/usr/bin/env python3
|
||||
import sqlite3, subprocess, re, os
|
||||
import sqlite3, subprocess, re, os, requests, time
|
||||
|
||||
DB = "sshd_failures.db"
|
||||
STATE = "cursor.txt"
|
||||
@@ -12,9 +12,25 @@ def get_cursor():
|
||||
def save_cursor(c):
|
||||
open(STATE, "w").write(c)
|
||||
|
||||
def geo(ip):
|
||||
r = requests.get(f"http://ip-api.com/json/{ip}", timeout=5).json()
|
||||
if r["status"] == "success":
|
||||
return r["country"], r["lat"], r["lon"]
|
||||
return None, None, None
|
||||
|
||||
def main():
|
||||
db = sqlite3.connect(DB)
|
||||
db.execute("CREATE TABLE IF NOT EXISTS failures(ts INTEGER, ip TEXT)")
|
||||
|
||||
db.execute("CREATE TABLE IF NOT EXISTS failures (ts INTEGER, ip TEXT)")
|
||||
|
||||
db.execute("""
|
||||
CREATE TABLE IF NOT EXISTS ip_geo (
|
||||
ip TEXT PRIMARY KEY,
|
||||
country TEXT,
|
||||
lat REAL,
|
||||
lon REAL
|
||||
)
|
||||
""")
|
||||
|
||||
cmd = ["journalctl", "-u", "sshd", "-o", "short-unix", "--no-pager"]
|
||||
cur = get_cursor()
|
||||
@@ -23,18 +39,10 @@ def main():
|
||||
|
||||
out = subprocess.check_output(cmd, text=True)
|
||||
|
||||
total = 0
|
||||
parsed = 0
|
||||
inserted = 0
|
||||
|
||||
for line in out.splitlines():
|
||||
total += 1
|
||||
|
||||
if not line or not line[0].isdigit():
|
||||
continue
|
||||
|
||||
parsed += 1
|
||||
|
||||
ts_str, msg = line.split(" ", 1)
|
||||
|
||||
try:
|
||||
@@ -43,15 +51,31 @@ def main():
|
||||
continue
|
||||
|
||||
m = PATTERN.search(msg)
|
||||
if m:
|
||||
db.execute("INSERT INTO failures VALUES (?, ?)", (ts, m.group(1)))
|
||||
inserted += 1
|
||||
if not m:
|
||||
continue
|
||||
|
||||
ip = m.group(1)
|
||||
|
||||
# store raw event
|
||||
db.execute("INSERT INTO failures VALUES (?, ?)", (ts, ip))
|
||||
|
||||
# check cache
|
||||
cached = db.execute(
|
||||
"SELECT 1 FROM ip_geo WHERE ip = ?",
|
||||
(ip,)
|
||||
).fetchone()
|
||||
|
||||
if not cached:
|
||||
country, lat, lon = geo(ip)
|
||||
db.execute(
|
||||
"INSERT OR REPLACE INTO ip_geo VALUES (?, ?, ?, ?)",
|
||||
(ip, country, lat, lon)
|
||||
)
|
||||
time.sleep(0.2)
|
||||
|
||||
db.commit()
|
||||
db.close()
|
||||
|
||||
print(f"lines={total} parsed={parsed} inserted={inserted}")
|
||||
|
||||
# save cursor
|
||||
out = subprocess.check_output(
|
||||
["journalctl", "-u", "sshd", "-n", "1", "-o", "export"],
|
||||
|
||||
Reference in new issue
Block a user